Roles & permissions
Who can do what
Three roles — Owner, Manager and Employee. Each one knows exactly what it can touch.
Owner
Whoever set the shop up. Full run of the place — staff, shifts, closed days, settings, billing, and everyone's hours.
- Sets up and runs the shop
- Adds, edits and removes staff
- Sets up every rule and setting
- Makes someone a Manager
- Looks after billing and the plan
Manager
EspressoA trusted member of staff the Owner promotes. The Owner picks exactly which parts they can run — it's never all or nothing.
- A separate switch per manager for staff, shifts, closed days, leave and hours
- A new Manager starts with leave and hours, nothing else
- Shop settings, billing, sub-QR codes and promoting managers stay Owner-only
- Still checks in and out like anyone else
Employee
Somebody on the floor, linked to the shop. Checks in, sees their own hours, asks for time off.
- Checks in and out by scanning the QR code
- Sees their own hours
- Asks for time off, a full day or part of one
- Cancels their own request while it's still waiting
- Sees their own shift and the closed days
The whole list
Who can do what, line by line
Every action, every role. No surprises.
| Action | Employee | Manager | Owner |
|---|---|---|---|
Today See their own day | Employee: Always allowed | Manager: Not available | Owner: Not available |
| See the whole day (everyone on it) | Employee: Not available | Manager: Comes from manage_attendance | Owner: Always allowed |
| See today's numbers | Employee: Not available | Manager: Always allowed | Owner: Always allowed |
| See how much leave is waiting | Employee: Not available | Manager: Always allowed | Owner: Always allowed |
Hours Check in and out by QR code | Employee: Always allowed | Manager: Always allowed | Owner: Always allowed |
| See their own hours | Employee: Always allowed | Manager: Always allowed | Owner: Always allowed |
| See everyone's hours | Employee: Not available | Manager: Comes from manage_attendance | Owner: Always allowed |
| Fix a day's hours | Employee: Not available | Manager: Comes from manage_attendance | Owner: Always allowed |
| Take a day off the record | Employee: Not available | Manager: Comes from manage_attendance | Owner: Always allowed |
| Add a missed day by hand | Employee: Not available | Manager: Comes from manage_attendance | Owner: Always allowed |
| Clock a colleague in or out | Employee: Owner decides, per manager | Manager: Comes from canCheckInOthers | Owner: Not available |
Leave Ask for their own time off | Employee: Always allowed | Manager: Always allowed | Owner: Always allowed |
| Put in leave for anyone | Employee: Not available | Manager: Comes from manage_leave | Owner: Always allowed |
| See their own leave | Employee: Always allowed | Manager: Always allowed | Owner: Always allowed |
| See everyone's leave | Employee: Not available | Manager: Comes from manage_leave | Owner: Always allowed |
| Approve or turn down leave | Employee: Not available | Manager: Comes from manage_leave | Owner: Always allowed |
| Cancel their own leave while it's waiting | Employee: Always allowed | Manager: Always allowed | Owner: Always allowed |
| Cancel anyone's leave | Employee: Not available | Manager: Comes from manage_leave | Owner: Always allowed |
Staff Add someone to the team | Employee: Not available | Manager: Comes from manage_employees | Owner: Always allowed |
| Edit someone's details | Employee: Not available | Manager: Comes from manage_employees | Owner: Always allowed |
| Remove someone (their hours stay) | Employee: Not available | Manager: Comes from manage_employees | Owner: Always allowed |
| Give out or take back a check-in card | Employee: Not available | Manager: Comes from manage_employees | Owner: Always allowed |
| Take back a registered phone | Employee: Not available | Manager: Comes from manage_employees | Owner: Always allowed |
| Excuse someone from a check-in rule | Employee: Not available | Manager: Comes from manage_checkin_exemptions | Owner: Always allowed |
| Link or unlink a login | Employee: Not available | Manager: Not available | Owner: Always allowed |
| Make someone a Manager, or undo it | Employee: Not available | Manager: Not available | Owner: Always allowed |
| Change what a Manager can do | Employee: Not available | Manager: Not available | Owner: Always allowed |
Shifts and closed days See the shifts | Employee: Always allowed | Manager: Always allowed | Owner: Always allowed |
| Create, edit and delete shifts | Employee: Not available | Manager: Comes from manage_shifts | Owner: Always allowed |
| Set different hours each day | Employee: Not available | Manager: Comes from manage_shifts | Owner: Always allowed |
| See the closed days | Employee: Always allowed | Manager: Always allowed | Owner: Always allowed |
| Create, edit and delete closed days | Employee: Not available | Manager: Comes from manage_closures | Owner: Always allowed |
The shop and its settings See the shop's details | Employee: Always allowed | Manager: Always allowed | Owner: Always allowed |
| Rename the shop | Employee: Not available | Manager: Not available | Owner: Always allowed |
| Set up shop WiFi only | Employee: Not available | Manager: Not available | Owner: Always allowed |
| Set up one phone per person | Employee: Not available | Manager: Not available | Owner: Always allowed |
| Set up near the shop only | Employee: Not available | Manager: Not available | Owner: Always allowed |
| Set up NFC tap check-in | Employee: Not available | Manager: Not available | Owner: Always allowed |
| Set up card check-in | Employee: Not available | Manager: Not available | Owner: Always allowed |
| Make or revoke an API key | Employee: Not available | Manager: Not available | Owner: Always allowed |
| Pair a kiosk | Employee: Not available | Manager: Not available | Owner: Always allowed |
| Make or edit sub-QR codes | Employee: Not available | Manager: Not available | Owner: Always allowed |
| Delete the shop | Employee: Not available | Manager: Not available | Owner: Always allowed |
Billing See the current plan | Employee: Always allowed | Manager: Always allowed | Owner: Always allowed |
| Move up or down a plan | Employee: Not available | Manager: Not available | Owner: Always allowed |
| Look after the payment card | Employee: Not available | Manager: Not available | Owner: Always allowed |
How this is enforced, underneath
There are four levels. Every request is checked against them before anything happens.
Read-only on the shop's data. Everyone linked to the shop gets this.
The named capabilities — manage_employees, manage_shifts, manage_closures, manage_leave, manage_attendance — handed out one at a time to each Manager. The Owner holds all of them without being given them.
Rename or delete the shop, change settings, look after billing, mint sub-QR codes, promote managers.
Adds hours and leave authority over that QR's own staff, on top of anything they already hold shop-wide.
Note: Each capability is handed over on purpose, one manager at a time. A Manager with only manage_leave can approve leave but can't edit the staff list. A Manager with everything except manage_attendance still sees only their own hours. The same check runs on every API endpoint, so there's no way round it.
Ready to set up your team?
Create your shop, add your staff, and hand a bit of it to the people you trust.